# How to solve \_geoip\_expired\_database

**URL:** <https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583>\
**Category:** Logstash\
**Created:** [November 7, 2023, 4:06am UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583 "2023-11-07T04:06:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [November 7, 2023, 4:06am UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/1 "2023-11-07T04:06:17Z")

</div>

Hi,

I've been experiencing an issue with the GeoIP filter here. So, at the beginning of my logstash deployment, the GeoIP filter was working well but recently I saw a tag on all my documents that said \_geoip\_expired\_database. do you know how to solve this?

since this is a production environment, if there is a URL that logstash should be able to access, what is the URL? I need to whitelist it

Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 7, 2023, 5:59am UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/2 "2023-11-07T05:59:23Z")

</div>

Perhaps take a look at this..

> **[Geoip filter plugin | Logstash Reference \[8.10\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-geoip.html#plugins-filters-geoip-database_auto)**

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [November 7, 2023, 6:46am UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/3 "2023-11-07T06:46:34Z")

</div>

i tried to disable `xpack.geoip.downloader.enabled` in `logstash.yml` and the GeoIP fields are back again in each document. but in this situation, my GeoIP database is not up to date right? To keep my logstash up to date, is it enough just to be connected to the internet? or is there any specific URL that logstash must be able to connect to?

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [November 7, 2023, 9:30am UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/4 "2023-11-07T09:30:04Z")

</div>

> [@yuswanul](#):
>
> but in this situation, my GeoIP database is not up to date right? To keep my logstash up to date, is it enough just to be connected to the internet? or is there any specific URL that logstash must be able to connect to?

sorry, I think It could be a misunderstanding. I can't edit it but this is the right one

> but in this situation, my GeoIP database is not up to date right? To keep my GeoIP database up to date, is it enough just to be connected to the internet?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 7, 2023, 12:13pm UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/5 "2023-11-07T12:13:13Z")

</div>

> [@yuswanul](#):
>
> To keep my GeoIP database up to date, is it enough just to be connected to the internet?

You would need to have `xpack.geoip.downloader.enable` as true to enable the auto-update and your logstash would need internet access.

If you set it as `false` your databases will not be updated even if you connect to the internet.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 7, 2023, 5:24pm UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/6 "2023-11-07T17:24:25Z")

</div>

> [@yuswanul](#):
>
> To keep my logstash up to date, is it enough just to be connected to the internet? or is there any specific URL that logstash must be able to connect to?

That is more of a MaxMind question than a logstash question. The API requires access to DNS and port 443, but it doesn't seem to document what URL it accesses. You might be able to find that by sniffing the network traffic.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 7, 2023, 5:53pm UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/7 "2023-11-07T17:53:15Z")

</div>

> [@Badger](#):
>
> The API requires access to DNS and port 443, but it doesn't seem to document what URL it accesses. You might be able to find that by sniffing the network traffic.

It is not in the documentation, but it is present on the [`logstash.yml`](https://github.com/elastic/logstash/blob/main/config/logstash.yml) reference file.

```auto
#xpack.geoip.downloader.enabled: true
#xpack.geoip.downloader.endpoint: "https://geoip.elastic.co/v1/database"

```

Just needs to allow traffic for `geoip.elastic.co` on port `443`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2023, 5:53pm UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583/8 "2023-12-05T17:53:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
